PatchDayAlert

CVE

CVE-2026-57148

0field notes · 1digest CVSS 9.8

The verdict

PraisonAI's platform ships with a hardcoded default JWT signing key ('dev-secret-change-me') that's active whenever the PLATFORM_JWT_SECRET environment variable isn't set. Since the platform also defaults to dev mode, an unauthenticated attacker can forge a valid JWT for any user or workspace owner and impersonate them. If you deployed PraisonAI without explicitly setting that secret, you're wide open.

Patch urgency · Patch immediately


Daily digests